On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

April 20th, 2009

Mac botnet being used in DDOS attacks

Posted by Jason D. O'Grady @ 8:24 pm

Categories: Hack, Mac OS, Security

Tags: Software, Apple Macintosh, Researcher, Malware, Distributed Denial Of Service, Desktops, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security

Back in January pirated versions of iWork ‘09 being shared on P2P networks were discovered to contain a trojan horse called “iWorkServices.” The author of the malware did his thing by adding a malicious binary to the trial version of the software package.

ZDNet’s own Ryan Naraine in “iBotnet” notes that researchers at Symantec claim that the resulting botnet of thousands of Macs is already being used for nefarious purposes.

Writing in the current issue of Virus Bulletin (subscription required), researchers Mario Ballano Barcena and Alfredo Pesoli found two malware variants — OSX.Iservice and OSX.Iservice.B — using different techniques to obtain the user’s password and take control of the infected Mac machine.

The symptom of an infected Mac is a PHP script, running as root, launching attacks against an unknown Web site as described in this blog entry. It’s being described as the “first real attempt to create a Mac botnet.”

The scariest part of Naraine’s piece comes at the end

“The code indicates that, wherever possible, the author tried to use the most flexible and extendible approach when creating it – and therefore we would not be surprised to see a new, modified variant in the near future,” the researchers added.

I guess the lesson here is to avoid downloading illicit software from P2P sites and to scan your Mac ASAP if you’ve been, ahem, promiscuous in your choice of software distribution systems.

Image: joseloya’s Flickr photostream

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 36 Talkback(s)
It was not installed without user and root user permissions!
There is a big difference between a root user entering a password to install software compared to botnets aka spyware being installed in the background without the user even knowing.

This is no... (Read the rest)
Posted by: ralphrides Posted on: 04/23/09 You are currently: a Guest | | Terms of Use
What OS is affected by this malware?  NonZealot | 04/20/09
Hey, you missed one  Fred Fredrickson | 04/21/09
Conficker = nonissue  JT82 | 04/21/09
I see...  msalzberg | 04/21/09
Bypassed Security? No.  mkleinpaste@... | 04/22/09
So let me get this right...  914four | 04/22/09
Yeah your right....  daMan25 | 04/21/09
Universal Malware?  Canticus | 04/21/09
My suggestion is ...  914four | 04/22/09
Switch to Windows is DUMB  cmgalaxy | 04/22/09
Malware limited to certain types of software only?  NonZealot | 04/20/09
Good point  honeymonster | 04/21/09
The amazing thing  LiquidLearner | 04/21/09
I recall the answer used to be "Because they have to enter a password".  ye | 04/21/09
Like this one?  NonZealot | 04/21/09
...amazing  kc117mx | 04/23/09
In Defense of Apple Mac Security  no_zd_user_name | 04/21/09
Oh my God ! Noooooo!  kd5auq | 04/21/09
RE: Mac botnet being used in DDOS attacks  jazzspaz | 04/21/09
Taking your chances...  phatkat | 04/21/09
Why not use AV progs  UK_PJC | 04/22/09
RE: Mac botnet being used in DDOS attacks  shellcodes_coder | 04/21/09
RE: Mac botnet being used in DDOS attacks  archer75 | 04/22/09
No, you're not right.  payton@... | 04/22/09
this would stop it.  pcguy777 | 04/22/09
RE: Mac botnet being used in DDOS attacks  mixxitman03@... | 04/22/09
Cool Doesn't Equal Sophisticated, Anyway  nottheusual1 | 04/22/09
Hardly a Trojan  DocNasty | 04/22/09
*virii (or: please god make it stop!!!) REPRISE  DeusExMachina | 04/22/09
re: *virii (or: please god make it stop!!!) REPRISE  hiccius doccius | 04/22/09
Eh? What brought that on?  Edouin | 04/22/09
RE: Mac botnet being used in DDOS attacks  Baer | 04/22/09
RE: Mac botnet being used in DDOS attacks  bklooste | 04/22/09
RE: Mac botnet being used in DDOS attacks  garthermath | 04/23/09
RE: Mac botnet being used in DDOS attacks  clarnT | 04/23/09
It was not installed without user and root user permissions!  ralphrides | 04/23/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here